Support Questions
Find answers, ask questions, and share your expertise
Announcements
Alert: Welcome to the Unified Cloudera Community. Former HCC members be sure to read and learn how to activate your account here.

impala kerberos issues

impala kerberos issues

Explorer

Hi All - we have added disk space to the all the nodes in our cluster and restarted each node. after the restart everything is working fine now and Impala from Hue browser is also working but we have a haproxy configured on one node for impala for applications from applications to connect - this is not working.

these are the logs we see on the impala daemons. Please suggest how this can be resolved.

Thanks in advance.

3 REPLIES 3

Re: impala kerberos issues

Explorer

these are the errors on logs: 

SASL message (Kerberos (external)): GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Wrong principal in request)
TThreadPoolServer: Caught TException: SASL(-13): authentication failure: GSSAPI Failure: gss_accept_sec_context

Re: impala kerberos issues

Super Guru

@IVenkatesh,

 

Make sure your applications are connecting to the HAProxy server and not directly to the Impala daemons themselves.  If you have configured a load balancer, you'll need to use it in order to authenticate via Kerberos.

See if that works... if not, then let us know.

Re: impala kerberos issues

Explorer

Hi bgooley - thank you for the response.

we checked and can see on haproxy logs that applications are connecting proxy and not to daemons directly.

on cloudera manager Impala Daemons Load Balancer properties , i see proxy server and port is configured on executors section. please advise if there is anything else to be verified.